漏洞列表 353571
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2025-13300
itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection
MEDIUM 6.9 2025-11-17
itsourcecode Web-Based Internet Laboratory Management System itsourcecode web-based_internet_laboratory_management_system
CVE NVD
CVE-2025-36299
IBM Planning Analytics Information Disclosure
MEDIUM 4.3 2025-11-17
IBM IBM Planning Analytics Local ibm planning_analytics_local +1个
CVE NVD
CVE-2025-13299
itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection
MEDIUM 6.9 2025-11-17
itsourcecode Web-Based Internet Laboratory Management System itsourcecode web-based_internet_laboratory_management_system
CVE NVD
CVE-2025-13298
itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection
MEDIUM 6.9 2025-11-17
itsourcecode Web-Based Internet Laboratory Management System itsourcecode web-based_internet_laboratory_management_system
CVE NVD
CVE-2025-13297
itsourcecode Web-Based Internet Laboratory Management System controller.php sql injection
MEDIUM 6.9 2025-11-17
itsourcecode Web-Based Internet Laboratory Management System itsourcecode web-based_internet_laboratory_management_system
CVE NVD
CVE-2025-34323
Nagios Log Server < 2026R1.0.1 Local Privilege Escalation via Writable Scripts and Sudo Rules
HIGH 8.5 2025-11-17
Nagios Log Server nagios log_server +1个
CVE NVD
CVE-2025-34322
Nagios Log Server < 2026R1.0.1 Authenticated Command Injection via Natural Language Queries
HIGH 8.6 2025-11-17
Nagios Log Server nagios log_server +1个
CVE NVD
CVE-2025-55059
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
MEDIUM 4.8 2025-11-17
Rumpus FTP Server maxum rumpus
CVE NVD
CVE-2025-55058
CWE-20 Improper Input Validation
MEDIUM 4.5 2025-11-17
Rumpus FTP Server maxum rumpus
CVE NVD
CVE-2025-55057
Multiple CWE-352 Cross-Site Request Forgery (CSRF)
MEDIUM 4.5 2025-11-17
Rumpus FTP Server maxum rumpus
CVE NVD
CVE-2025-64756
glob CLI: Command injection via -c/--cmd executes matches with shell:true
HIGH 7.5 2025-11-17
isaacs node-glob isaacs node-glob +1个
CVE NVD
CVE-2025-55056
Multiple CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scri...
MEDIUM 4.8 2025-11-17
Rumpus FTP Server maxum rumpus
CVE NVD
CVE-2025-55055
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
MEDIUM 6.8 2025-11-17
Rumpus FTP Server maxum rumpus
CVE NVD
CVE-2025-64758
@dependencytrack/frontend Vulnerable to Persistent Cross-Site-Scripting via Welcome Message
MEDIUM 4.8 2025-11-17
DependencyTrack frontend
CVE NVD
CVE-2025-64342
ESF-IDF's ESP32 Bluetooth Controller Has an Invalid Access Address Vulnerability
MEDIUM 6.9 2025-11-17
espressif esp-idf espressif esp-idf +3个
CVE NVD
CVE-2025-58407
GPU DDK - TOCTOU bug affecting psFWMemContext->uiPageCatBaseRegSet
HIGH 7.4 2025-11-17
Imagination Technologies Graphics DDK imaginationtech ddk
CVE NVD
CVE-2025-13193
Libvirt: information disclosure via world-readable vm snapshots
MEDIUM 5.5 2025-11-17
Red Hat Red Hat Enterprise Linux 10 Red Hat Red Hat Enterprise Linux 6 +3个
CVE NVD
CVE-2025-13291
Campcodes Supplier Management System confirm_order.php sql injection
MEDIUM 6.9 2025-11-17
Campcodes Supplier Management System campcodes supplier_management_system
CVE NVD
CVE-2025-58410
GPU DDK - Multiple calls into PhysmemGEMPrimeExport can inherit write access permission for an existing read-only dma_buf import PMR
HIGH 7.5 2025-11-17
Imagination Technologies Graphics DDK imaginationtech ddk +5个
CVE NVD
CVE-2025-62519
phpMyFAQ has Authenticated SQL Injection in Configuration Update Functionality
HIGH 7.2 2025-11-17
thorsten phpMyFAQ phpmyfaq phpmyfaq
CVE NVD